Skip to main content
Vulnerability Database/CVE-2026-80145

CVE-2026-80145: Lantronix SLC/EMG RCE Vulnerability

CVE-2026-80145 is a command injection vulnerability in Lantronix SLC8000/SLC9000 and EMG devices that allows authenticated attackers to execute arbitrary commands as root. This post covers technical details, affected versions, and mitigation.

Updated:

CVE-2026-80145 Overview

CVE-2026-80145 is a command injection vulnerability [CWE-78] affecting Lantronix autonomous out-of-band management devices, including the SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 product lines. The flaw resides in the set cifs password command exposed through the terminal and CLI interfaces. Authenticated attackers holding the services permission can inject shell metacharacters into the password parameter, which is passed unsanitized into a system() call and executed as root. Successful exploitation results in complete loss of confidentiality, integrity, and availability on the device and can pivot into any serial-attached downstream systems.

Critical Impact

Attackers with services permission gain unauthenticated root shell execution on out-of-band console servers, compromising downstream serial-attached infrastructure.

Affected Products

  • Lantronix SLC8000 and SLC9000 running firmware prior to v9.7.0.2
  • Lantronix EMG8500 and EMG7500 running firmware prior to v9.7.0.1
  • Lantronix SLB882, SLCx-03, and SLCx-02 (all firmware versions, end-of-life)

Discovery Timeline

  • 2026-09-22 - CVE-2026-80145 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-80145

Vulnerability Analysis

The vulnerability exists in the CLI handler for the set cifs password command, which is used to configure the Common Internet File System (CIFS) share password for remote logging or backup targets. The command handler concatenates user-supplied input directly into a shell command string and invokes system() without sanitizing shell metacharacters such as backticks, semicolons, or $() substitutions.

Because the CLI process runs as root on Lantronix out-of-band devices, any injected command executes with full privileges. The devices sit at a sensitive point in the network, typically providing serial console access to routers, switches, firewalls, and servers, so compromise extends beyond the appliance itself.

Root Cause

The root cause is missing input validation on the password parameter passed to a shell interpreter [CWE-78]. The affected firmware trusts CLI input from authenticated services-role users and forwards the raw string to system(). No allowlist, escaping, or use of a safer execve-style API is applied.

Attack Vector

An attacker must first authenticate to the terminal or CLI interface with an account holding the services permission. This can be achieved over the network via SSH or Telnet, or through the local serial console. Once authenticated, the attacker issues set cifs password with a crafted value containing shell metacharacters, causing the injected payload to run as root. See the VulnCheck advisory and the Revrb Lantern write-up for exploitation details.

No verified proof-of-concept code is published in the enriched data. Refer to the advisories above for the sanitized exploitation walkthrough.

Detection Methods for CVE-2026-80145

Indicators of Compromise

  • CLI audit log entries containing set cifs password with shell metacharacters such as ;, |, `, $(, or newline sequences in the password field.
  • Unexpected root-owned processes spawned by the CLI handler, or new outbound connections originating from the appliance shortly after CLI activity.
  • Creation or modification of files outside normal firmware paths, including new SSH authorized_keys entries or cron jobs on the appliance.

Detection Strategies

  • Forward CLI and syslog output from Lantronix devices to a centralized log platform and alert on set cifs password invocations containing non-alphanumeric characters.
  • Baseline outbound network traffic from out-of-band management devices and flag deviations, since these appliances typically initiate very limited connections.
  • Correlate authentication events for services-role accounts with subsequent CLI command execution to identify anomalous administrative sessions.

Monitoring Recommendations

  • Continuously monitor administrative access to out-of-band management VLANs and restrict source addresses to a hardened jump-host range.
  • Track firmware versions across the Lantronix fleet and alert when devices report versions below 9.7.0.2 (SLC) or 9.7.0.1 (EMG).
  • Review serial-attached device logs for lateral movement following any suspected appliance compromise.

How to Mitigate CVE-2026-80145

Immediate Actions Required

Patch Information

Lantronix has published fixed firmware versions 9.7.0.2R1 for SLC8000/SLC9000 and 9.7.0.1R2 for EMG7500/EMG8500. The SLB882, SLCx-03, and SLCx-02 product lines will not receive a patch and should be decommissioned. Additional context is available in the VulnCheck advisory.

Workarounds

  • Remove the services permission from all accounts that do not strictly require CIFS configuration capability.
  • Restrict management interface reachability to a dedicated administrative network segment protected by ACLs and jump hosts.
  • Disable Telnet and require SSH with key-based authentication for the CLI interface until patches are applied.
  • Monitor and alert on any invocation of the set cifs password command until the affected devices are upgraded or replaced.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.